Skip to main content
TobiasHan
New Member
July 2, 2018
Question

Fortigate SIP Problem (or Portchange without NAT)

  • July 2, 2018
  • 2 replies
  • 3607 views

Hello,

 

i have a fortigate 500 with FortiOS 5.4.6 on it.

 

The Firewall works since over 2 years, but since friday i have the problem, that one Port change the destination port.

 

Normally the policy (and static route) says: all traffic destination xx.xxx.62.3 goes over vpn to destination (Source und Destination Port 5060). Now or since friday comes the traffic on source port 5060 and goes out at 15060.

The traffic now not goes in the VPN TUnnel, and directly into the wan and was blocked by policy violation.

 

What can i do, to fix the problem.

 

Interestingly it works between, without make a change at the firewall.

 

Thanks for any advise and kind regards

Tobias

 

    2 replies

    razor
    Visitor III
    July 2, 2018

    Do you have SIP ALG enabled?

    emnoc
    New Member
    July 2, 2018

    the cli cmd diag debug flow is your  friend here and what do you mean by policy and route ?  Is this policyBasedRoute?

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!